Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Dell computers bundled with backdoor that blurts hardware fingerprint to websites (Mo' Badness)
The Register ^ | Nov 25, 2015 | Shaun Nichols

Posted on 11/24/2015 6:50:06 PM PST by dayglored

Analysis

Dell ships Windows computers with software that lets websites slurp up the machine's exact specifications, warranty status, and other details without the user knowing.

This information can be used to build a fingerprint that potentially identifies a person while she browses across the web. It can be abused by phishers and scammers, who can quote the information to trick victims into thinking they're talking to a legit Dell employee. And, well, it's just plain rude.

A website created by a bloke called Slipstream - previously in these pages for exposing security holes in UK school IT software - shows exactly how it can work.

This proof-of-concept code exploits a weakness in the design of Dell's support software to access the computer's seven-character service tag - an identifier that Dell's support website uses to look up information on the machine, including the model number, installed components, and warranty data.

Visit Slip's page above to see it in action - assuming you have a Dell running Dell Foundation Services. Be warned, though, it does play some fun chiptune music, so mute your speakers if you're still at work.

Slipstream says his website does not exploit the eDellRoot root CA certificate that turned up in new models of Dell laptops and PCs - but the Dell Foundation Services software that uses the dodgy cert.

As documented by Duo Security, Dell Foundation Services starts up a web server on TCP port 7779 that accepts requests for the service tag.

All a website has to do is, in JavaScript, request this URL:

http://localhost:7779/Dell%20Foundation%20Services/eDell/IeDellCapabilitiesApi/REST/ServiceTag
and the foundation services returns exactly that - the service tag. No authentication required. This serial code can then be fed into Dell's support site to look up information about the machine.

The Register has tested the proof-of-concept site and verified that it does indeed pull up the service code on an Inspiron 15 series laptop bought in July. Slipstream also confirmed to The Reg that his script works even when the vulnerable root CA cert is removed by Dell's prescribed methods.

Aside from the possibility that a scammer could use the support number to gain user trust for a phony tech support call or other security con job, the proof-of-concept demonstrates just how deeply a third party can probe into a user's system by exploiting Dell's now-notorious support tools.

Dell was thrust into the spotlight yesterday when researchers first broke word of eDellRoot, a rogue certificate authority quietly installed on Windows machines that can be exploited by man-in-the-middle attackers to decrypt people's encrypted web traffic.

The Texas PC-slinger said the issue was merely a mishap related to its user support tools. Dell bristled at suggestions the flaw should be considered malware or adware, but nonetheless it has provided users with a removal tool.

The American biz has also pushed a software update that will automatically remove the vulnerable root CA cert from its machines.


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: dell; security; windowspinglist; wtfweretheythinking
Geez, these Dell guys don't have the first clue how to secure a system. They DO know how to open it up to hacking, though.
1 posted on 11/24/2015 6:50:06 PM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: dayglored; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Analysis of the Dell security problem and proof-of-concept test ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 11/24/2015 6:50:54 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

3 posted on 11/24/2015 6:51:41 PM PST by ClearCase_guy (I support anything which diminishes the Muslim population.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ClearCase_guy
DUDE! You're getting your ass handed to you in a sling!!
4 posted on 11/24/2015 6:59:25 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

anyone who doesn’t do a clean/fresh install of the OS on ANY OEM computer they buy is just asking for trouble anyway. That’s the first thing I do when I get a new PC


5 posted on 11/24/2015 7:24:36 PM PST by FunkyZero (... I've got a Grand Piano to prop up my mortal remains)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I have a Dell desktop computer,
bought March of this year.
...
in task manager,
indicates ..Dell Foundation Services, Stopped

...
any suggestions?


6 posted on 11/24/2015 7:25:46 PM PST by RockyTx
[ Post Reply | Private Reply | To 1 | View Replies]

To: RockyTx
> in task manager, indicates ..Dell Foundation Services, Stopped ... any suggestions?

I'd leave it stopped. Disabled, if that's an option.

7 posted on 11/24/2015 7:27:17 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 6 | View Replies]

To: RockyTx

My Dell Inaperation has none of the issues listed.


8 posted on 11/24/2015 7:27:34 PM PST by boomop1 (Term limits is the only source of change.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: RockyTx

My Dell Inspiration has none of the issues listed.


9 posted on 11/24/2015 7:28:50 PM PST by boomop1 (Term limits is the only source of change.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: FunkyZero
anyone who doesn’t do a clean/fresh install of the OS on ANY OEM computer they buy is just asking for trouble anyway. That’s the first thing I do when I get a new PC

Easy for a geek.
10 posted on 11/24/2015 8:02:13 PM PST by Old Yeller (Obama's Iran nuclear deal - The Devil is in the details.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Old Yeller
Na, Os install of windows is very simple, nothing at all to be afraid of as long as you have any documents you need backed up somewhere. Seriously, the worst part is patching it after you install it.. takes half a day to catch it back up.

OEM,s load PC's with so much bloatware, unneeded tools and other garbage, half the system resources are used up by junk right out of the box. It really is bad.

Best bet is to always get a Windows install CD (purchase the media with the PC) so you can install it clean without using their system restore option (that just puts all the garbage back again).

11 posted on 11/24/2015 9:44:53 PM PST by FunkyZero (... I've got a Grand Piano to prop up my mortal remains)
[ Post Reply | Private Reply | To 10 | View Replies]

To: dayglored

Just go to add/remove and uninstall the entire Dell Foundation Services bloatware package. It’s nearly useless anyway: all it does is provide Dell your service tag if you call them for service, something you can see on the service tag label on your PC and read out over phone. It’s ridiculous to have a whole service running in the background at all times, consuming RAM and CPU.

Just say no to all bloatware. Say no to DFS and uninstall it.


12 posted on 11/24/2015 11:08:04 PM PST by catnipman (Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Dell ships Windows computers with software

This is all you need to know. If you have a Dell system that you took out of the box and started using, you're vulnerable. If you're a corporate customer not using their CTO or OEM channel stuff, you're in the clear.

I was forced to script something to check all of our machines for this nonsense, and out of 1200 physical systems, not a single one had this root certificate.

I'm not defending Dell, this is ridiculous on their part, but for corporate customers, this is much ado about nothing.

13 posted on 11/25/2015 6:31:39 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FunkyZero
That's the first thing I do when I get a new PC

So, if it comes preloaded with a Windows OS...you'll buy another copy of Windows and effectively pay for the OS software twice?

14 posted on 11/25/2015 9:32:45 AM PST by Bloody Sam Roberts (Democracy is not freedom. Democracy is simply majoritarianism. It is incompatible with real freedom.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Bloody Sam Roberts
> So, if it comes preloaded with a Windows OS...you'll buy another copy of Windows and effectively pay for the OS software twice?

Depends on how much you value your time and frustration dealing with the crapware that came with the OEM installation. You can often buy hardware without Windows installed, save the Windows tax, and install a clean copy bought elsewhere.

When you use Windows, you must be prepared to pay, and pay some more, and then spend inordinate amounts of time fixing and cleaning and repairing. Or risk malware with "cracked" versions to save a few bucks.

Personally, I prefer to run my Windows in VMs (virtual machines) hosted on either Mac or Linux workstations. That said, I have three Windows installs "on the metal" at home, dual booted.

15 posted on 11/25/2015 7:37:22 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored
You can often buy hardware without Windows installed, save the Windows tax, and install a clean copy bought elsewhere.

That's what I thought you meant but your comment in #5 led me to believe the PC had been bought with an OS.

16 posted on 11/26/2015 6:38:06 AM PST by Bloody Sam Roberts (Democracy is not freedom. Democracy is simply majoritarianism. It is incompatible with real freedom.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Bloody Sam Roberts

No, you already have the OEM license generally when you buy the PC. Just pay a little extra and get the DVD media (they don’t include that, only their customized “restore” media) so you can install it clean and without all the garbage the stick in it. I don’t think it’s right, but they do charge extra for the windows media. It’s a manageable cost though... usually 10 or 20 bucks or something like that. The install key is on a sticker on your computer, all you need is the install media and use your existing key from the sticker.


17 posted on 11/26/2015 7:33:01 AM PST by FunkyZero (... I've got a Grand Piano to prop up my mortal remains)
[ Post Reply | Private Reply | To 14 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson